Page 2 of 2 FirstFirst 12
Results 11 to 17 of 17
  1. #11
    Join Date
    Jun 2016
    Location
    Suffolk VA
    Posts
    590
    Plugin Contributions
    0

    Default Re: Login restrictions (and possible security problem)

    Quote Originally Posted by swguy View Post
    OK, just an idea based on your original post, where you asked

    > when a person with a certain profile logs in, the screen goes directly to the code they need to see and use?

    What you (probably) have now - most menus turned off, no home page content - is probably intuitive enough that your staff can figure it out.
    I'm sure it is. I just don't want those people to see that there may be more content that they don't have access to. Or get an explicit message that more is present if only they had some other login credentials. But I really like the idea of that being a configuration option as well, because not everyone may feel as strongly about that point as I do. I had an employee who tried to poke around in another employee's computer to see what he could find out about the company. Granted, not being able to see even the home page isn't going to prevent someone from trying that stunt anyway. But it will lessen (I hope) the assumption that someone else might have something more interesting to look at.

    The plugin I'm working on is to assist with order packing, to reduce errors in shipping. The people who are doing that will have no other responsibility in the company and there's no reason for them to have access to anything else (or to see that there is anything else).

  2. #12
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    12,495
    Plugin Contributions
    88

    Default Re: Login restrictions (and possible security problem)

    An admin with restricted permissions, i.e. they're not allowed to view orders, customers, sales reports or whos-online will only see menu tabs containing their permitted tools and, on the home page, the current traffic as well as the base statistics ... neither of which I think give away sensitive information.

  3. #13
    Join Date
    Jun 2016
    Location
    Suffolk VA
    Posts
    590
    Plugin Contributions
    0

    Default Re: Login restrictions (and possible security problem)

    Quote Originally Posted by lat9 View Post
    An admin with restricted permissions, i.e. they're not allowed to view orders, customers, sales reports or whos-online will only see menu tabs containing their permitted tools and, on the home page, the current traffic as well as the base statistics ... neither of which I think give away sensitive information.
    True, and if I can't do a different home page for them, or take them directly to their login page, that will not be unacceptable. I'm still trying to get my program registered on the admin side so I can test it, so I've had to put the home page part on the back burner for the moment. I'm not sure what I'm doing wrong there yet, but if I still can't figure it out in another day or so, I'll ask for help with that.

  4. #14
    Join Date
    Feb 2006
    Location
    Tampa Bay, Florida
    Posts
    9,699
    Plugin Contributions
    123

    Default Re: Login restrictions (and possible security problem)

    Guidance on adding an admin page:

    https://docs.zen-cart.com/dev/code/creating_menu/
    That Software Guy. My Store: Zen Cart Modifications
    Available for hire - See my ad in Services
    Plugin Moderator, Documentation Curator, Chief Cook and Bottle-Washer.
    Do you benefit from Zen Cart? Then please support the project.

  5. #15
    Join Date
    Jun 2016
    Location
    Suffolk VA
    Posts
    590
    Plugin Contributions
    0

    Default Re: Login restrictions (and possible security problem)

    Quote Originally Posted by swguy View Post
    Guidance on adding an admin page:

    https://docs.zen-cart.com/dev/code/creating_menu/
    Yes, that's what I'm using as a guide. I finally figured it out--'TOOLS' was missing from the declaration in ADMIN/includes/language/english/extra_definitions/

    As often happens, I learned a lot more by getting an error message 10 times than by getting it right the first time, lol. Now all I have to do is make the program itself work correctly. And then figure out how to fit it into the new plugin format. One step at a time. Thanks for your help.

  6. #16
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    12,495
    Plugin Contributions
    88

    Default Re: Login restrictions (and possible security problem)

    ... and if you're also looking to conditionally display the tool's output on the admin home-page, check out /admin/includes/modules/dashboard_widgets/RecentOrdersDashboardWidget.php.

    That widget restricts its home-page display to either super-user admins or those that have permissions to use the Customers :: Orders tool.

  7. #17
    Join Date
    Jun 2016
    Location
    Suffolk VA
    Posts
    590
    Plugin Contributions
    0

    Default Re: Login restrictions (and possible security problem)

    Thanks, I'll do that.

 

 
Page 2 of 2 FirstFirst 12

Similar Threads

  1. Login not working after install and possible SSL problem?
    By Clover in forum Basic Configuration
    Replies: 3
    Last Post: 26 Sep 2019, 08:51 PM
  2. Admin login problem: There was a security error when trying to login.
    By eddeford in forum Installing on a Linux/Unix Server
    Replies: 3
    Last Post: 27 Jan 2010, 03:59 PM
  3. Coupon restrictions and linked product problem
    By KTNaturals in forum General Questions
    Replies: 2
    Last Post: 10 Aug 2007, 02:48 AM
  4. Possible security problem - not sure
    By Rosalie in forum General Questions
    Replies: 1
    Last Post: 11 Jun 2007, 01:22 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR